PLACEHOLDER

Cookies

We only use cookies Tripsettled needs to work: to keep you signed in, to protect sign-in and sign-up, and to remember this choice. We don't use analytics or advertising cookies.

Read the cookie policy

Off: we don't use analytics yet. If we ever do, we'll ask for your permission here.

PLACEHOLDER

DRAFT — pending attorney review. An attorney has not reviewed this document yet, and it may change before its final version.

Privacy Policy

Version 0.4.0. In effect since October 3, 2026.

Includes the full and short privacy notices for Mexico (sections 18 and 19). For users in Mexico, the Spanish version of those sections is the official aviso de privacidad.

Version0.4.0
Effective dateOctober 3, 2026
ControllerOsvaldo Rodriguez (an individual)
AddressDallas, Texas, United States
Privacy contacttripsettled.app@gmail.com

The short version

1. Who is responsible for your data

Osvaldo Rodriguez, an individual (not a company) located in Dallas, Texas, United States, is the controller of your personal data in Tripsettled. In this policy, “we” and “us” refer to him. For any privacy matter, including rights requests, write to tripsettled.app@gmail.com. The person who handles those requests is Osvaldo Rodriguez.

2. Who this policy applies to

It applies to the data of:

It covers tripsettled.com, its subdomains (including the test version dev.tripsettled.com) and any app we publish later.

3. What data we process

3.1 Your account data

DataWhy
Email address (in lowercase) and whether it's verifiedTo identify you, let you sign in and send you service emails
The name your group seesTo show it to the members of your trips. You choose it when you accept the terms.
Preferred languageTo show you the app and emails in your language
Password, only if you set oneTo let you sign in. We never store your password: we store a value derived with the argon2id algorithm, which can't be turned back into the password.
Account status (active or deactivated) and internal identifierTo manage the account

3.2 Data we receive from Google, only if you choose to sign in with Google

Google sends us your Google account identifier, your email, whether Google has verified it, and your name. We keep the identifier to recognize you next time. When we create your account, we use your Google name to prefill the name your group will see; you can change it before you accept the terms, or later in My account. Google may also send your photo and language, but we don't keep them. We never receive your Google password or your contacts.

3.3 Data generated when you use the app

DataWhat it includes
SessionsA session token that we store as a hash; the start, last-activity and expiry dates; and the type of browser and operating system (for example, “Chrome / Android”). We don't store your IP address or your browser's full description.
Sign-in linksSingle-use tokens to sign in with a magic link or verify your email: the token's hash, what it's for, the email it was sent to, the email's language, and when it expires (15 minutes). For magic links, also the app page you'll return to after signing in. For verification links, the hash of a value that ties the link to the browser you signed up in.
Google sign-in in progressTemporary technical values that protect sign-in with Google (they last 10 minutes).
Document acceptanceWhich document you accepted, its version, the language you read it in, the date and time, and your confirmation that you are 18 or older.
ConsentsWhich consents you gave or withdrew (email notifications, sending documents to AI, health data), when, and their history.
Access listDuring the test phase, the emails of the people we invite to sign up, with an optional internal note on why we invited them (for example, “Lupe's friend, Oaxaca trip”). The note never contains sensitive data. See section 3.7.
Abuse protectionCounters of attempts (password sign-ins, link requests and sign-ups) in 15-minute or one-day windows, per IP address (or per network, if you use IPv6), per account or per email. For example, we limit password attempts per account and send at most 10 sign-in emails a day to the same address. Each counter is identified by a value we compute with a cryptographic function and a secret key (HMAC-SHA-256). These counters don't store the IP or the email, and they can't be worked out without the key.
Audit logWhich important action was taken (for example, creating the account, signing in, accepting documents, correcting your profile, changing a consent, exporting your data, deleting the account, or a change made by the administrator), who took it and when, with internal identifiers only.
Technical logsRequest ID, operation, result, duration and error type. They may include internal identifiers, but not your name, your email or what you write.
TelemetryServer performance and error data. Microsoft derives an approximate location (city, state, country) from the IP and then discards the IP.
Emails we send youYour address and the content of the email, which Microsoft processes to deliver it. Our emails have no tracking pixels or tracked links.

3.4 Your trip data

Some of these features arrive in upcoming versions of the app. When they are available, we will process:

Other people's data. You can add adults without an account to a trip (name or nickname and the data needed to plan) and minors as dependents (only name or nickname and whether they need a car seat). If you add someone, we process their data under this policy; that person can exercise their rights as explained in section 10.8.

3.5 Sensitive data and data we handle with extra care

3.6 What we don't collect

We don't ask for your precise location, your contacts, your photo, card details, passport numbers or government IDs. If you import a confirmation that contains them, we remove them before storing it. We don't use tracking technologies for advertising.

3.7 If we invited you and you don't have an account yet

During the test phase, only invited people can create an account. If you asked or agreed to be invited, we keep your email on the access list, sometimes with an internal note on why we invited you. We only use it to let you create your account; we don't send you anything until you ask to sign in.

4. How we use your data

4.1 Uses needed to provide the service

  1. Create and manage your account and verify your email.
  2. Let you sign in and keep your session secure.
  3. Send you service emails: sign-in links, verification, security notices and the notice that your account was deleted.
  4. Let you plan trips with your group and show each member what they're meant to see.
  5. Record which documents you accepted and which consents you gave.
  6. Protect the service and its users: usage limits, fraud and abuse prevention, security incident investigation and the audit log.
  7. Handle your rights and support requests.
  8. Operate, back up and maintain the service: technical logs, backups and bug fixes.
  9. Comply with legal obligations and defend our rights.

4.2 Uses that require your consent

These aren't needed to provide the service. You can say no or withdraw your consent at any time, and the rest of the app keeps working:

4.3 What we don't do

5. Legal grounds for using your data

UseUnited StatesMexico
Uses needed for the service (4.1)Needed to provide the service you asked for, disclosed in this policyNeeded to fulfill our legal relationship with you (art. 9, sec. IV of the law) and your consent when you accept this policy
Notifications, AI and analytics (4.2)Your consentYour express consent, which you can revoke (art. 7)
Health-related dietary restrictionsYour consent, as Texas law requires for sensitive dataYour express written consent, given with your account as the authentication mechanism (art. 8)
Expenses and payments between members, when availableNeeded to provide the serviceNeeded for the legal relationship (arts. 7 and 9, sec. IV) and your express consent when you accept this policy
Security, audit and legal complianceNeeded to protect the service and comply with the lawArts. 9, secs. I and IV
Access list (invited people without an account)Needed to give you the access you asked for or agreed toYour consent, when you ask for or agree to the invitation, with this policy available to you on the sign-in screen (art. 7)

In this table, “the law” is Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), published in the Diario Oficial de la Federación on March 20, 2025.

6. Who sees your data inside Tripsettled

7. Who we share your data with

We don't share your data with any other third parties. Today we don't make any data transfers that require your consent; if we ever need to, we will ask you first.

8. Where your data is stored and international transfers

Your data is stored on Microsoft Azure servers in the South Central US region, in Texas, United States. Emails are processed with Azure Communication Services in the United States. To deliver the service, some Microsoft components may process data in transit outside that region.

If you live in Mexico: your data leaves the country. We send it to Microsoft as our processor (encargado), which handles it only on our behalf and under a contract that requires it to protect your data. Under Mexican law (art. 2, sec. XX), sending data to a processor is not a transfer, but we're telling you so you know. If you choose to sign in with Google, Google handles your Google account data on its own servers, in several countries. The same goes for the emails you send us, which stay in our Gmail account.

9. How long we keep your data

DataHow long
Account, Google link, acceptances and consentsWhile you have an account. When you confirm your account deletion, they are erased immediately.
Accounts whose sign-up isn't completed (email not verified or terms not accepted)Deleted after 7 days
Account of someone who says they are under 18Deleted immediately
Access listUntil you delete your account or we remove you from the list. Not deleted with incomplete sign-ups.
SessionsWhile active; deleted 30 days after they end or expire
Sign-in links and temporary Google sign-in dataLinks are valid for 15 minutes and Google sign-in data for 10. They are deleted no later than 24 hours after they are used or expire.
Abuse protection counters24 hours
Audit log12 months; 24 months for records of rights requests. After you delete your account, only with your internal identifier, without your name or email.
Technical logs30 days
Telemetry30 days, without your name, email or IP
Emails you send us and our replies12 months after they're resolved; 24 months for rights requests
BackupsUp to 7 days

An automatic cleanup runs once a day and deletes each item once its period is over, so deletion can take up to one extra day. The details, including what happens to what you contributed to shared trips, are in the Retention and Deletion Policy.

10. Your rights and how to use them

10.1 In the app

In My account you can, without writing to us:

10.2 By email

Write to tripsettled.app@gmail.com to exercise any right, including the ones not available in the app, or to appeal a decision. Include:

Our email is a Gmail account, so Google stores what you send us (section 7). Don't attach government IDs or other documents unless we ask for them.

10.3 How we verify your identity

If you make the request from the app while signed in, you're already verified. If you write to us, we will ask you to confirm the request from your account email. Only if that isn't possible will we ask for another way to verify your identity, and only for the information strictly needed. If you act on behalf of someone else (legal representative or authorized agent), we will need a document that proves the authorization.

10.4 Deadlines and cost

10.5 If you live in the United States

Under your state's law (for example, the Texas Data Privacy and Security Act or the California Consumer Privacy Act), you can:

Appeals. If we deny your request, you can appeal by writing “Appeal” to tripsettled.app@gmail.com within 60 days of our response. We will reply in writing within 60 days. If we confirm the denial, you can file a complaint with the Texas Attorney General (https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint) or, if you live in California, with the California Privacy Protection Agency (https://cppa.ca.gov/).

Categories of data in the last 12 months (using California's categories):

CategoryExamplesSourcePurposeDisclosed toSold or shared for advertising?
IdentifiersEmail, internal identifier, Google identifierYou; GoogleUses 1 to 9 in section 4.1Service providers (Microsoft)No
Personal recordsNameYou; GoogleUses 1 to 4Service providersNo
Internet activitySessions, browser and system type, technical logsYour browserUses 2, 6 and 8Service providersNo
Approximate locationCity, state or country derived from the IP in telemetryYour connectionUse 8Service providersNo
Sensitive personal informationEmail with password (as a hash)YouUse 2Service providersNo

10.6 If you live in Mexico: ARCO rights

You have the right to:

You can exercise them in the app (10.1) or by email (10.2). We will reply through the same channel you used. We can only refuse in the cases the law provides, for example if your identity isn't verified, if we don't hold the data, or if a law requires us to keep it, and we will always explain why.

If you disagree with our response, or if we don't respond in time, you can file a data protection request (solicitud de protección de datos) with the Secretaría Anticorrupción y Buen Gobierno within 15 business days of our response or of the response deadline (art. 40).

10.7 Withdrawing your consent and limiting the use of your data

10.8 People without an account and minors

11. Minors

Tripsettled is not directed at people under 18 and we don't allow them to have accounts. We don't knowingly collect data directly from minors. A minor only appears in the app as a dependent of a responsible adult, with their name or nickname and whether they need a car seat; their dietary restrictions are stored only with that adult's consent. If someone says they are under 18 when accepting the terms, we delete their account immediately. If we learn in any other way that an account belongs to a minor, we close it and delete its data.

12. Security

We protect your data with administrative, technical and physical measures, including:

No system is 100% secure. If a security breach significantly affects your rights, we will tell you right away and explain what to do, as the applicable laws require.

13. Cookies

Today we only use strictly necessary cookies: your session cookie, two temporary ones that protect signing in with Google and signing up with a password, and one that remembers your cookie choice. We don't use advertising or analytics cookies. The details are in the Cookie Policy.

14. Artificial intelligence

Today no feature uses AI and we don't send data to any AI provider. When that changes, we will ask for your consent before sending your documents. The details are in the AI Use Policy.

15. Opt-out signals (Global Privacy Control)

We don't sell your data or share it for advertising, so there's nothing to opt out of. If we add analytics in the future, we will treat your browser's Global Privacy Control signal as a refusal of analytics.

16. Changes to this policy

17. Contact and authorities

18. Full privacy notice for Mexico (aviso de privacidad integral)

This notice follows article 15 of Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (DOF March 20, 2025). The sections above give the details.

I. Identity and address of the controller. Osvaldo Rodriguez, an individual, located in Dallas, Texas, United States. Contact: tripsettled.app@gmail.com. The person designated to handle data subjects' requests is Osvaldo Rodriguez.

II. Personal data we process.

III. Purposes.

IV. Options and means to limit the use or disclosure of your data. The consents in My account, the visibility options for each item in your trips, and the email tripsettled.app@gmail.com.

V. How to exercise ARCO rights. From My account (download your data, correct your profile, delete your account) or by email to tripsettled.app@gmail.com, with the information in section 10.2. We respond within 20 business days and, if granted, carry it out within the following 15 business days. It's free. If you're not satisfied, you can go to the Secretaría Anticorrupción y Buen Gobierno (section 10.6).

VI. Withdrawing consent. From My account or by email to tripsettled.app@gmail.com, with no retroactive effect (section 10.7).

VII. Processors and transfers. We send your data to Microsoft Corporation, our processor, which hosts and processes it in the United States. If you email us, your messages stay in our Gmail account, which Google LLC runs under its own terms. We don't make transfers that require your consent. We would only disclose data to authorities in the cases in article 36 of the law (for example, when legally required or to defend a right in court). If we ever wanted to make a transfer that does require your consent, we would ask you first.

VIII. Cookies and similar technologies. We only use strictly necessary cookies: session, protection of sign-in with Google, protection of password sign-up, and a record of your cookie choice. We don't use them to collect data for advertising. You can delete them in your browser, but then you won't be able to stay signed in. Details in the Cookie Policy.

IX. Changes to the notice. We will publish every change in the app's Legal section with its version and date. We will notify you of important changes by email and in the app, and ask you to accept them (section 16).

19. Short privacy notice for Mexico (aviso de privacidad simplificado)

Osvaldo Rodriguez, an individual located in Dallas, Texas, United States, is responsible for your personal data in Tripsettled. We use your email, your name and what you enter in your trips to create and protect your account, let you plan trips with your group, and comply with the law. With your consent, which you can refuse or withdraw at any time, we also use them to send you email notifications and, when those features exist, to process documents with AI and to store health-related dietary restrictions, which are sensitive data. You can limit the use of your data from My account or by writing to tripsettled.app@gmail.com. Your data is stored in the United States. Read the full privacy notice in this app's Legal section.

Change history

VersionDateChange
0.4.02026-10-03Before taking effect: the controller (Osvaldo Rodriguez, an individual, Dallas, Texas) and the privacy email, which is a Gmail account (sections 7, 8, 9 and 10.2). What you accept doesn't change.
0.3.02026-10-03New cookie that protects password sign-up; more detail on sign-in links (return page, browser binding) and on attempt and email limits; the automatic cleanup runs once a day. What you accept doesn't change.
0.2.02026-10-03Before taking effect: explains the access list for invited people (section 3.7), the name prefilled from Google, immediate deletion when someone says they are under 18, how account deletion is confirmed, the secret key behind the abuse counters, and emails without tracking. Technical logs and telemetry: 30 days. What you accept doesn't change.
0.1.02026-10-03First draft.
Back to top